{
  "query": {
    "kev": "1",
    "page": "53"
  },
  "count": 20,
  "total": 1734,
  "page": 53,
  "limit": 20,
  "updated": {
    "cves": "2026-10-08T06:48:55.607Z",
    "kev": "2026-10-08T06:49:55.245Z",
    "epss": "2026-10-08T07:00:55.738Z",
    "breaches": "2026-10-08T06:48:55.302Z",
    "posts": "2026-10-08T06:48:55.607Z"
  },
  "links": {
    "web": "https://spydr.io/threats?kev=1&page=53",
    "next": "https://spydr.io/threats.json?kev=1&page=54"
  },
  "coverage": {
    "cves_published_since": "2026-06-10",
    "days": 120,
    "also": "every CVE in CISA KEV"
  },
  "unscored_hidden": 0,
  "warnings": [],
  "results": [
    {
      "id": "CVE-2017-0147",
      "url": "https://spydr.io/cve/CVE-2017-0147",
      "published": "2017-03-17T00:59:04.087Z",
      "modified": "2026-06-17T00:57:09.933Z",
      "score": 7.5,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.99693,
      "epss_percentile": 0.99951,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft Corporation"
      ],
      "products": [
        "Microsoft Corporation Windows SMB"
      ],
      "cwes": [],
      "description": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka \"Windows SMB Information Disclosure Vulnerability.\""
    },
    {
      "id": "CVE-2017-0022",
      "url": "https://spydr.io/cve/CVE-2017-0022",
      "published": "2017-03-17T00:59:00.680Z",
      "modified": "2026-06-17T00:56:56.453Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.18069,
      "epss_percentile": 0.97126,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft Corporation"
      ],
      "products": [
        "Microsoft Corporation XML Core Services"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site, aka \"Microsoft XML Information Disclosure Vulnerability.\""
    },
    {
      "id": "CVE-2017-0005",
      "url": "https://spydr.io/cve/CVE-2017-0005",
      "published": "2017-03-17T00:59:00.197Z",
      "modified": "2026-06-17T00:56:54.710Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.11022,
      "epss_percentile": 0.95804,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft Corporation"
      ],
      "products": [
        "Microsoft Corporation Windows GDI"
      ],
      "cwes": [],
      "description": "The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka \"Windows GDI Elevation of Privilege Vulnerability.\" This vulnerability is different from those described in CVE-2017-0001, CVE-2017-0025, and CVE-2017-0047."
    },
    {
      "id": "CVE-2016-3298",
      "url": "https://spydr.io/cve/CVE-2016-3298",
      "published": "2016-10-14T02:59:13.893Z",
      "modified": "2026-06-17T00:45:27.033Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.33332,
      "epss_percentile": 0.98336,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer",
        "microsoft windows 7",
        "microsoft windows server 2008",
        "microsoft windows vista"
      ],
      "cwes": [],
      "description": "Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka \"Internet Explorer Information Disclosure Vulnerability.\""
    },
    {
      "id": "CVE-2016-3351",
      "url": "https://spydr.io/cve/CVE-2016-3351",
      "published": "2016-09-14T10:59:24.357Z",
      "modified": "2026-08-14T05:16:53.547Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.26286,
      "epss_percentile": 0.97956,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer",
        "microsoft edge"
      ],
      "cwes": [],
      "description": "Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka \"Microsoft Browser Information Disclosure Vulnerability.\""
    },
    {
      "id": "CVE-2016-4657",
      "url": "https://spydr.io/cve/CVE-2016-4657",
      "published": "2016-08-25T21:59:02.150Z",
      "modified": "2026-06-17T00:47:58.727Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.66788,
      "epss_percentile": 0.99276,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apple"
      ],
      "products": [
        "apple iphone os"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site."
    },
    {
      "id": "CVE-2016-4656",
      "url": "https://spydr.io/cve/CVE-2016-4656",
      "published": "2016-08-25T21:59:01.087Z",
      "modified": "2026-06-17T00:47:58.547Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.23626,
      "epss_percentile": 0.97758,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apple"
      ],
      "products": [
        "apple iphone os"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app."
    },
    {
      "id": "CVE-2016-4655",
      "url": "https://spydr.io/cve/CVE-2016-4655",
      "published": "2016-08-25T21:59:00.133Z",
      "modified": "2026-06-17T00:47:58.357Z",
      "score": 5.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.33353,
      "epss_percentile": 0.98338,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "apple"
      ],
      "products": [
        "apple iphone os"
      ],
      "cwes": [],
      "description": "The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app."
    },
    {
      "id": "CVE-2016-6367",
      "url": "https://spydr.io/cve/CVE-2016-6367",
      "published": "2016-08-18T18:59:01.463Z",
      "modified": "2026-06-17T00:50:54.407Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.22583,
      "epss_percentile": 0.97664,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "cisco adaptive security appliance software"
      ],
      "cwes": [
        "CWE-77"
      ],
      "description": "Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA."
    },
    {
      "id": "CVE-2016-6366",
      "url": "https://spydr.io/cve/CVE-2016-6366",
      "published": "2016-08-18T18:59:00.117Z",
      "modified": "2026-06-17T00:50:54.163Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.87565,
      "epss_percentile": 0.99757,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "cisco"
      ],
      "products": [
        "cisco pix firewall software",
        "cisco adaptive security appliance software",
        "cisco asa 1000v cloud firewall software"
      ],
      "cwes": [
        "CWE-120"
      ],
      "description": "Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON."
    },
    {
      "id": "CVE-2016-0162",
      "url": "https://spydr.io/cve/CVE-2016-0162",
      "published": "2016-04-12T23:59:26.410Z",
      "modified": "2026-06-17T00:37:02.340Z",
      "score": 4.3,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
      "score_source": "NVD",
      "epss": 0.22012,
      "epss_percentile": 0.97608,
      "exploited": true,
      "kev": {
        "added": "2022-05-24",
        "due": "2022-06-14",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "microsoft"
      ],
      "products": [
        "microsoft internet explorer"
      ],
      "cwes": [],
      "description": "Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka \"Internet Explorer Information Disclosure Vulnerability.\""
    },
    {
      "id": "CVE-2019-8720",
      "url": "https://spydr.io/cve/CVE-2019-8720",
      "published": "2023-03-06T23:15:10.287Z",
      "modified": "2026-10-07T18:17:08.973Z",
      "score": 8.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01556,
      "epss_percentile": 0.74407,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "webkitgtk",
        "wpewebkit",
        "redhat"
      ],
      "products": [
        "webkitgtk"
      ],
      "cwes": [
        "CWE-119"
      ],
      "description": "A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues."
    },
    {
      "id": "CVE-2022-20821",
      "url": "https://spydr.io/cve/CVE-2022-20821",
      "published": "2022-05-26T14:15:08.123Z",
      "modified": "2026-06-17T04:25:11.087Z",
      "score": 6.5,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.11471,
      "epss_percentile": 0.95916,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Cisco"
      ],
      "products": [
        "Cisco IOS XR Software"
      ],
      "cwes": [
        "CWE-200"
      ],
      "description": "A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to the container filesystem, and retrieve information about the Redis database. Given the configuration of the sandboxed container that the Redis instance runs in, a remote attacker would be unable to execute remote code or abuse the integrity of the Cisco IOS XR Software host system."
    },
    {
      "id": "CVE-2021-1048",
      "url": "https://spydr.io/cve/CVE-2021-1048",
      "published": "2021-12-15T19:15:14.917Z",
      "modified": "2026-06-17T03:30:51.917Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.01,
      "epss_percentile": 0.61656,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "google"
      ],
      "products": [
        "Android"
      ],
      "cwes": [
        "CWE-416"
      ],
      "description": "In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-204573007References: Upstream kernel"
    },
    {
      "id": "CVE-2021-0920",
      "url": "https://spydr.io/cve/CVE-2021-0920",
      "published": "2021-12-15T19:15:11.017Z",
      "modified": "2026-06-17T03:30:39.430Z",
      "score": 6.4,
      "severity": "medium",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.0082,
      "epss_percentile": 0.55919,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "linux",
        "google",
        "debian"
      ],
      "products": [
        "Android"
      ],
      "cwes": [
        "CWE-362",
        "CWE-416"
      ],
      "description": "In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel"
    },
    {
      "id": "CVE-2021-30883",
      "url": "https://spydr.io/cve/CVE-2021-30883",
      "published": "2021-08-24T19:15:16.403Z",
      "modified": "2026-06-17T03:51:04.443Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.14721,
      "epss_percentile": 0.96595,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS and iPadOS",
        "Apple macOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, macOS Big Sur 11.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.."
    },
    {
      "id": "CVE-2020-1027",
      "url": "https://spydr.io/cve/CVE-2020-1027",
      "published": "2020-04-15T15:15:21.010Z",
      "modified": "2026-06-17T03:00:15.313Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04547,
      "epss_percentile": 0.91328,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows Server",
        "Microsoft Windows 10 Version 1909 for 32-bit Systems",
        "Microsoft Windows 10 Version 1909 for x64-based Systems",
        "Microsoft Windows 10 Version 1909 for ARM64-based Systems",
        "Microsoft Windows Server, version 1909 (Server Core installation)",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows Server, version 1903 (Server Core installation)"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1003."
    },
    {
      "id": "CVE-2019-18426",
      "url": "https://spydr.io/cve/CVE-2019-18426",
      "published": "2020-01-21T21:15:16.147Z",
      "modified": "2026-06-17T02:25:01.227Z",
      "score": 8.2,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N",
      "score_source": "NVD",
      "epss": 0.67859,
      "epss_percentile": 0.99306,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Facebook"
      ],
      "products": [
        "Facebook WhatsApp Desktop"
      ],
      "cwes": [
        "CWE-79"
      ],
      "description": "A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and local file reading. Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message."
    },
    {
      "id": "CVE-2020-0638",
      "url": "https://spydr.io/cve/CVE-2020-0638",
      "published": "2020-01-14T23:15:32.503Z",
      "modified": "2026-08-12T05:17:27.463Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.0237,
      "epss_percentile": 0.83303,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Known"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Microsoft"
      ],
      "products": [
        "Microsoft Windows",
        "Microsoft Windows 10 Version 1903 for ARM64-based Systems",
        "Microsoft Windows 10 Version 1903 for 32-bit Systems",
        "Microsoft Windows 10 Version 1903 for x64-based Systems",
        "Microsoft Windows Server",
        "Microsoft Windows Server, version 1903 (Server Core installation)",
        "Microsoft Windows 10 Version 1909 for 32-bit Systems",
        "Microsoft Windows 10 Version 1909 for x64-based Systems",
        "Microsoft Windows Server, version 1909 (Server Core installation)",
        "Microsoft Windows 10 Version 1909 for ARM64-based Systems"
      ],
      "cwes": [
        "CWE-59"
      ],
      "description": "An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'."
    },
    {
      "id": "CVE-2019-7287",
      "url": "https://spydr.io/cve/CVE-2019-7287",
      "published": "2019-12-18T18:15:22.130Z",
      "modified": "2026-06-17T02:40:23.570Z",
      "score": 7.8,
      "severity": "high",
      "cvss_version": "3.1",
      "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "score_source": "NVD",
      "epss": 0.04579,
      "epss_percentile": 0.91379,
      "exploited": true,
      "kev": {
        "added": "2022-05-23",
        "due": "2022-06-13",
        "action": "Apply updates per vendor instructions.",
        "ransomware": "Unknown"
      },
      "ssvc_exploitation": "active",
      "vendors": [
        "Apple"
      ],
      "products": [
        "Apple iOS"
      ],
      "cwes": [
        "CWE-787"
      ],
      "description": "A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4. An application may be able to execute arbitrary code with kernel privileges."
    }
  ],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
